Security is our
first product
Every line of code, every architecture decision, every policy at Zupay starts with the question: is this secure? Here's how we protect your business and your customers.
Certified to the highest global standards
PCI DSS Level 1
The highest level of payment card industry compliance. Audited annually by a QSA.
SOC 2 Type II
Independent audit of our security, availability, and confidentiality controls.
ISO 27001
Internationally recognised information security management certification.
GDPR Compliant
Full compliance with EU data protection regulations. DPA available on request.
Defence in depth
Encryption everywhere
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Card data never touches your servers — tokenised at the point of entry.
Real-time fraud detection
ML models trained on billions of transactions score every payment in real time. Less than 0.01% false positive rate — legitimate payments sail through.
3DS2 & SCA
Full 3D Secure 2 support with intelligent exemption management to maximise approval rates while meeting strong customer authentication requirements.
Role-based access control
Granular permissions for every team member. Full audit logs of every API call, dashboard action, and settings change — immutable and always available.
99.99% uptime
Multi-region active-active architecture with automatic failover. Real-time status at status.zupay.io. Post-incident reports published within 24 hours.
Bug bounty programme
Security researchers are rewarded for responsibly disclosing vulnerabilities. Our programme is managed via HackerOne with payouts up to $50,000.
Security questions?
Our security team is available to answer detailed questions or provide documentation for enterprise due diligence.